KDC service hangs on start + cert error in event log at every boot



After upgrading a Win2000 server (PDC) to Server 2003 R2, I get the old 'at
least one service or driver failed to start' popup on the logon screen at
every boot.

There are two messages in the event log that look related, an error and a
warning:

error
SCM event 7022,
"The Kerberos Key Distribution service hung on starting"

warning
KDC event 20,
"The currently selected KDC certificate was once valid, but now is
invalid and no replacement was found"


I ran 'netdiag /test:kerberos /v' and 'certutil -DCInfo', neither reports
an error.

I started MMC with the certificates plugin, and looked up the KDC
certificate by the serial number that certutil reported: it is OK and still
valid until February 2009, but after a new reboot the warning and the hang
at startup both just came back.


Does anyone have an idea what might cause this?
.



Relevant Pages

  • Re: [Fwd: Re: problem in sending AS_REQ]
    ... # use "kdc =" if realm admins haven't put SRV records into DNS ... I have used openssl program to generate the mycert.pem and key, ... server's certificate is not trusted. ... The MIT client will not send pkinit information until the server ...
    (comp.protocols.kerberos)
  • Re: self-signing certificate
    ... saw that my self-signed certificate was under the ... Now warnings at all when opening with medium security set. ... And, if correct, why the warning? ...
    (microsoft.public.access.security)
  • Re: [Fwd: Re: problem in sending AS_REQ]
    ... # use "kdc =" if realm admins haven't put SRV records into DNS ... The client will not attempt preauth if the ... server's certificate is not trusted. ... The MIT client will not send pkinit information until the server ...
    (comp.protocols.kerberos)
  • Certsrv and Autoenrollment problem
    ... The "Windows default" Policy Module logged the following warning: ... V1 Certificate Template could not be loaded. ... see Help and Support Center at ...
    (microsoft.public.windows.server.sbs)
  • Re: New Users (accounts) cant see/get to My Docs or Email
    ... certificate was listed as 'not to be trusted'. ... All SBS issued certificates are going to toss a warning. ... My Outlook can't conect to the server. ... Is there a recommended way to delete the Exchange user from the ...
    (microsoft.public.windows.server.sbs)